Protegrity Research Finds Security and Governance Delays are Creating a Hidden AI Friction Tax

Organizations are beginning to move AI initiatives beyond experimentation and into everyday business operations. As AI systems become further integrated into enterprise workflows, many enterprises are discovering that securing AI for production is more complex than expected and encountering new hurdles that can delay deployment and limit AI capabilities.

Protegrity, a global leader in data and knowledge security, today launched The State of AI Friction: Why Enterprise AI Deployment is Slower, Costlier, and More Limited Than Expected, an independent research report produced by Enterprise Management Associates (EMA). Based on a survey of IT and security leaders, the report examines how security reviews, compliance processes, sensitive data access and trust concerns prevent organizations from realizing the full value of enterprise AI- barriers referred to as “AI friction” in the report. 

“AI has quickly become a business imperative, but many organizations are discovering that getting AI into production is far more difficult than building a proof of concept,” said James Rice, VP of Product Marketing at Protegrity. “This research helps to better understand where those barriers exist and what they’re costing enterprises. The findings show that security, governance and compliance have become critical business considerations that can either accelerate AI adoption or slow it dramatically. Organizations that address this friction will be in a much stronger position to realize AI’s full value.” 

The findings indicate that enterprise AI deployment is moving faster than the security and governance infrastructure supporting it, causing organizations to struggle when moving projects from pilot to production. According to the research: 

  • While organizations continue to scale AI and give agents access to production systems, 82.9% say security or compliance reviews have delayed AI projects from reaching production.
  • Among organizations that experienced delays, 66.7% were stalled for at least one month, with nearly 30% delayed four months or longer. 

Security concerns also affect what reaches production. 81.6% of organizations report deploying AI in a diminished state because of security concerns, reducing agent autonomy or restricting access to critical enterprise data. Security review ranked as the leading production bottleneck, followed by difficulty securing sensitive data, infrastructure costs and audit and compliance requirements.

The report identifies the combined impact as the “AI friction tax,” the hidden cost organizations pay through delayed deployments, reduced AI functionality and mounting governance overhead. Rather than stemming from a lack of AI investment or technical capability, obstacles are increasingly tied to how organizations protect sensitive data and manage risk.

“Security, governance and compliance are now the primary barriers preventing enterprises from moving AI into production at the pace the business demands,” said Chris Steffen, Vice President of Research, Information Security at EMA “The findings make clear that many organizations are compensating by deploying AI with reduced capabilities rather than the functionality originally intended. That compromise is widening the gap between AI investment and business value, while adding avoidable costs, delays and operational inefficiencies.” 

The report further highlights a widening gap between enterprise AI ambitions and the infrastructure supporting them. Nearly 70% of surveyed organizations already have AI agents capable of “autonomous action” capabilities such as writing to databases or triggering external APIs, yet only 19.7% report deploying highly autonomous AI systems. These findings suggest that enterprise AI infrastructure has not kept pace with the security and governance requirements needed to support autonomous agents at scale.

The report concludes that reducing AI friction requires moving security and governance closer to where AI operates. Rather than relying on manual reviews or controls designed for traditional environments, organizations are looking to embed protection directly into AI workflows, pipelines and agents. Among respondents, 91.5% said AI-ready data without roadblocks by embedding protection inside the workflow would be very or extremely valuable.

 

Join our LinkedIn group Information Security Community!

No posts to display